Particle.news
Download on the App Store

Zoom Patches ‘Zoomsday’ Zero-Click Flaw Found With Public AI

Security researchers say publicly available AI sped the creation of a working exploit and that the case raises questions about how vulnerabilities are scored and disclosed.

Overview

  • Researchers at A Security say they used publicly available AI models to find and prototype a working exploit against Zoom’s annotation protocol in under a day with fewer than 20 prompts.
  • On Tuesday, August 11, 2026, A Security published a technical write-up and Zoom published fixes and CVE assignments, including CVE-2026-53413, 53414 and 53415 for memory-corruption, buffer over-read and use-after-free bugs.
  • The flaws sat in Zoom’s annotator and its proprietary annotation protocol, which opens direct channels between a screen sharer and viewers and let specially crafted messages corrupt client memory for remote code execution.
  • Zoom says it rolled out client and server-side patches across Workplace, Rooms, Meeting SDK and VDI builds and that many client fixes were shipped in June and July; there are no confirmed in-the-wild exploit reports.
  • The episode raises enterprise risk because zero-click RCE can be silent and cross-platform, and it has prompted debate over AI’s role in lowering exploit barriers plus disputes about CVSS scoring and crediting of findings.